FortiAnalyzer
FortiAnalyzer can receive logs and Windows host events directly from endpoints connected to EMS, and you can use FortiAnalyzer to analyze the logs and run reports.
haziqsulaiman
Article Id 382683
Description

This article describes why FortiAnalyzer stops receiving real-time logs while logs are being restored from backup.

Scope FortiAnalyzer.
Solution

When restoring logs on FortiAnalyzer, users may notice that real-time logs are not received until the restoration is complete.

 

This is because certain logging daemons are stopped when log restoration is initiated.

 

init_restore.png

 

This can also be verified by checking the PID and uptime of the daemons.

 

Before restore:

 

after.png

 

After restore:

 

before.png

 

The daemons will restart once the restore process is complete:

 

complete_restore.png

 

The following daemons are seen to be restarted when performing logs restoration:

 

fortilogd
logfiled
oftpd
sqllogd